Lazarus_Group__2020__securelist.com-Lazarus_covets_COVID-19-related_intelligence.pdf
ID: 9a93b669-e7b3-4863-8ba8-d9f7dfb9f1cb
STIX ID: report--9a93b669-e7b3-4863-8ba8-d9f7dfb9f1cb
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2020-12-24
Last Modified Date: 2020-12-24
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky describes two Lazarus-attributed intrusions targeting COVID-19-related organizations: a wAgent infection at a health ministry (in-memory loader, DLL injection, Security Support Provider persistence) and a Bookcode compromise of a vaccine-developing pharmaceutical firm (loader, injected backdoor, supply-chain/spearphishing vectors). The report documents post-exploitation actions (SAM dumps, network reconnaissance, lateral movement), lists C2 infrastructure and file/hash IOCs, maps techniques to MITRE ATT&CK, and concludes Lazarus is actively seeking COVID-19 research intelligence.
